Skip to content

Glossary

GDPR (General Data Protection Regulation)

The GDPR is the EU regulation that sets the rules for processing personal data, the obligations of controllers and processors and the rights of data subjects, and applies directly in every Member State.

The regulation applies to the processing of personal data by automated means and to manual processing where the data form part of a filing system. Personal data is any information relating to an identified or identifiable individual. Territorially it covers processing in the context of the activities of an establishment in the EU, wherever the processing takes place, and controllers and processors outside the EU when they offer goods or services to people in the EU or monitor their behavior. It distinguishes the controller, who determines the purposes and means of processing, from the processor, who processes on the controller's behalf; that relationship must be governed by a contract.

Processing must follow the principles of lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality. Overarching all of them is accountability: the controller must be able to demonstrate compliance. Every processing operation needs a legal basis — consent, performance of a contract, a legal obligation, vital interests, a public task or legitimate interests — while special categories such as health or biometric data are subject to additional conditions.

Obligations include maintaining records of processing activities, data protection by design and by default, a data protection impact assessment for high-risk processing, appointing a data protection officer where required, appropriate technical and organizational security measures, notifying the supervisory authority of a personal data breach, and informing affected individuals where the breach poses a high risk to their rights. Separate rules govern transfers of data to third countries.

Individuals have the rights to be informed and to access their data, to rectification, erasure, restriction of processing, portability and objection, including objection to direct marketing, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Enforcement lies with independent supervisory authorities — in Slovenia the Information Commissioner — whose corrective powers extend to limiting or banning processing; alongside administrative fines, individuals also have a right to compensation. The regulation leaves certain matters to national law, in Slovenia to the personal data protection act.

Back to glossary

Ready to strengthen security across your organization?

Contact us to see how our turnkey solutions can build a safer, more resilient organization.